Boletines de Vulnerabilidades |
IBM Security Bulletin: Vulnerability in RC4 stream cipher affects IBM Algorithmics One Core, Algo Risk Application, and Counterparty Credit Risk (CVE-2015-2808) |
|
| Software afectado | IBM |
|
The RC4 algorithm, as used in the TLS protocol and SSL protocol, could allow a remote attacker to obtain sensitive information. An attacker could exploit this vulnerability to remotely expose account credentials without requiring an active man-in-the-middle session. Successful exploitation could allow an attacker to retrieve sensitive information. This vulnerability is commonly referred to as "Bar Mitzvah Attack". CVE(s): CVE-2015-2808 Affected product(s) and affected version(s): More info: https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_vulnerability_in_rc4_stream_cipher_affects_ibm_algorithmics_one_core_algo_risk_application_and_counterparty_credit_risk_cve_2015_2808?lang=en_us |
|














